hardMultiple Select
CCSP Practice Question: A cloud security architect is designing a…
A cloud security architect is designing a DevSecOps pipeline for a multi-cloud environment. Which THREE practices should be included to ensure security is integrated early? (Select THREE)
⚠ Common exam trap
The CCSP exam often tests the concept of 'shift-left' by including late-stage security activities (like post-deployment scanning or production DAST) as distractors, tempting candidates who confuse 'security testing' with 'early integration'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scanning dependencies for known vulnerabilities in the CI pipeline
Option A is correct because scanning dependencies for known vulnerabilities in the CI pipeline (e.g., with SCA tools like Dependabot, Snyk, or OWASP Dependency-Check) shifts detection of vulnerable third-party libraries to the earliest build stage, before artifacts are promoted. Option D is correct because IaC security scanning on Terraform templates (e.g., with Checkov, tfsec, or Terrascan) catches misconfigurations such as public S3 buckets or overly permissive security groups before any infrastructure is provisioned. Option E is correct because performing SAST scans in the IDE or during pull requests (e.g., with SonarQube, Semgrep, or CodeQL) gives developers immediate feedback on insecure code patterns at the point of authorship, which is the earliest possible integration point. Option B does not belong because scanning container images only after production deployment is a reactive, post-deployment control rather than an early-shift-left practice. Option C does not belong because DAST against production is a late-stage, runtime test that exercises a live environment and cannot prevent defects from reaching production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scanning dependencies for known vulnerabilities in the CI pipeline
Why this is correct
Scanning dependencies in CI detects known vulnerabilities in third-party libraries before artefacts are built, shifting remediation left. This satisfies the multi-cloud DevSecOps requirement by catching supply-chain flaws early, when fixes are cheaper and before code reaches deployment.
- ✗
Scanning container images after they are deployed to production
Why it's wrong here
Scanning images after deployment detects vulnerabilities only once workloads are already running in production, so flaws are not caught before release. It is tempting because runtime scanning covers the exact artefacts deployed and catches drift, which suits continuous monitoring of long-lived production registries rather than shift-left gating.
- ✗
Running DAST against the production environment
Why it's wrong here
Running DAST against production tests a live environment rather than gating code before release, and it risks corrupting real data; early integration requires testing in the pipeline against non-production targets. It appeals because production is the most realistic target, which suits periodic assurance of an already-deployed application.
- ✓
Running IaC security scanning on Terraform templates before deployment
Why this is correct
Scanning Terraform templates before deployment catches misconfigurations such as public buckets or permissive security groups while infrastructure is still declarative code. This satisfies the early-integration requirement by preventing insecure cloud resources rather than detecting them after provisioning.
- ✓
Performing SAST scans in the IDE or during pull requests
Why this is correct
SAST in the IDE or during pull requests analyses source code for flaws before merge, giving developers immediate feedback. This satisfies the requirement to integrate security early by blocking vulnerable code at authoring time, ahead of build and deployment stages.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.